ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

Storm-2945 uses hotel Wi-Fi fake updates to deploy CornFlake RAT

Source headline: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 4 hours ago

Intelligence Summary

A hijacked hotel Wi-Fi network was used to deliver a fake browser update. The update served the CornFlake remote access trojan to victims who visited captive portals. Microsoft reports that the malware can capture webcam images, microphone audio, and keystrokes. Researchers link the operation, dubbed CaptiveCrunch, to Storm-2945. This matters because shared Wi-Fi plus user-driven update prompts can lead to full device surveillance and credential theft. Users should avoid installing updates prompted through captive portals and keep browsers and OS components up to date.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#credential-theft #malware #rat #surveillance #captive-portal #wifi-hijack
Original reporting The Hacker News Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Open original source